Executive brief
A vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services allows an attacker to disrupt search operations. By sending malicious requests, a user with low-level access can cause the system to hang or crash repeatedly, leading to a total denial of service. Additionally, the attacker may be able to view a limited amount of sensitive data that they are not authorized to see.
Technical details
A vulnerability exists in the Forge component of Oracle Commerce Guided Search Platform Services version 11.4.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to trigger a complete denial of service (DoS) by causing the service to hang or crash frequently. Furthermore, the vulnerability permits unauthorized read access to a subset of data managed by the Platform Services. The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Commerce Guided Search Platform Services 11.4.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory